Rows marked inferred are OSINT-extracted enrichment for actors without a MITRE Group ID — treat as analyst assessment, not authoritative ATT&CK attribution.
| Technique | Name | Tactic | Observed use |
|---|---|---|---|
| T1561.002 ↗inferred | Disk Wipe: Disk Structure Wipe | Impact | overwrites the Master Boot Record, rendering machines unbootable (Symantec) |
| T1529 ↗inferred | System Shutdown/Reboot | Impact | forces reboot into an unbootable state (Symantec) |
| T1490 ↗inferred | Inhibit System Recovery | Impact | destroys systems with no recovery path (Symantec/Unit 42) |
| T1561.001 ↗inferred | Disk Wipe: Disk Content Wipe | Impact | wipes file contents across affected hosts (Symantec) |
| T1485 ↗inferred | Data Destruction | Impact | Disttrack overwrites files with garbage/ideological images (Symantec) |
| T1078 ↗inferred | Valid Accounts | Initial Access | pre-staged valid credentials (Greenbug-harvested) used before wiper detonation (Symantec/Unit 42) |
| T1570 ↗inferred | Lateral Tool Transfer | Lateral Movement | propagates the wiper across the network for coordinated detonation (Unit 42) |
Regional co-occurrence is association, not prediction. These techniques appeared alongside Shamoon Operators's activity across the tracked MENA roster — a TIE-style association computed on our corpus (not CTID's model), not a prediction of the next move. Ranked by support-adjusted lift (over-representation among actors like this one vs. the roster base rate, damped when few actors back it), so neither a merely-common technique nor a tiny-sample coincidence floats to the top. A hunting lead only; never recorded as observed. ICS techniques are excluded.
Which Microsoft 365 controls protect, detect, or respond to this actor's techniques — from the CTID Mappings Explorer (technique-level). Strength: significant / partial / minimal.
Defensive techniques that counter Shamoon Operators's TTPs, from MITRE D3FEND. The ATT&CK↔D3FEND link is mitigation-mediated — treat these as candidate countermeasures, not prescriptions.